Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10214

Опубликовано: 25 нояб. 2019
Источник: debian
EPSS Низкий

Описание

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-containers-imagenot-affectedpackage
singularity-containerfixed3.5.0+ds1-1package

Примечания

  • https://github.com/containers/image/issues/654

  • https://github.com/containers/image/pull/669

EPSS

Процентиль: 48%
0.00246
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 5 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS3: 6.4
redhat
почти 6 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS3: 5.9
nvd
больше 5 лет назад

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

suse-cvrf
около 5 лет назад

Security update for skopeo

suse-cvrf
больше 5 лет назад

Security update for skopeo

EPSS

Процентиль: 48%
0.00246
Низкий